Confidential mandate
Chief Information Officer — Cybersecurity Hub
Planned Hiring / New
CIO mandate in Hyderabad, India · Global Capability Centres
Build the secure digital workplace and information backbone that will let a Hyderabad cyber hub assume global responsibilities without compromising separation or evidence.
The mandate
A Hyderabad cybersecurity hub is moving from captive regional support to serving global security operations and engineering. Its enabling information estate was never designed for that status. Collaboration relies on exceptions, evidence is assembled manually for client assurance, specialist labs share dependencies with the corporate workplace, and several global connections lack clear service ownership. Expansion cannot proceed responsibly until the hub has an information environment equal to the obligations it will assume.
The new Chief Information Officer will lead approximately 850 employees and partners and steward an enabling-technology perimeter near ₹3,100 crore. The remit covers workplace, identity integration, collaboration, enterprise applications, service management, connectivity, data governance and the internal control evidence supporting the hub. Security product engineering and cyber defence remain with separate leaders. The CIO must make the boundary explicit while partnering with them on shared infrastructure and privileged workflows.
The objective is secure enablement, not maximum restriction. Analysts need timely access to global tools and data, but client segregation, residency and evidentiary standards differ. The CIO must create repeatable patterns, reduce bespoke exceptions and be prepared to delay new global scope where access, logging or recoverability cannot be demonstrated.
Basic information discipline also needs attention. Asset records do not consistently show whether devices support workplace, laboratory or production activity, and service ownership sometimes ends at a vendor contract. A reconciled configuration and dependency record must become usable during change and incident response, not maintained solely for periodic assurance.
Why this seat is open
The previous captive model did not justify a standalone CIO. The board created the position as planned new hiring once global expansion was approved, allowing four to six months for a rigorous search. Existing technology managers continue to operate services and will report into the successful executive after organisation design. No incumbent is being displaced.
What you will own
- Define the information and workplace architecture required for global cyber services, including explicit separation from security-product environments.
- Standardise identity, access request, logging and evidence patterns across served clients while preserving their contractual differences.
- Establish ownership, service objectives and recovery for every material application and connection used by the hub.
- Reduce manual assurance through reliable configuration, asset, access and incident evidence.
- Govern technology demand and investment, rejecting client expansion that depends on unsupported exceptions.
- Rationalise local tools and vendors where common group services meet performance and security needs.
- Build a CIO organisation spanning enterprise architecture, operations, applications, data governance and service experience.
- Operate transparent incident and change governance with the Chief Risk Officer and cyber leaders.
The first 12 months
The first quarter will produce a complete service and dependency map, with critical access exceptions and unsupported applications identified. The CIO will settle architecture boundaries and agree minimum information controls for new global work. Two high-risk manual assurance processes should be selected for redesign.
By month eight, common access and evidence services will support the first expansion wave, and every critical enabling service will have an owner and tested recovery plan. The CIO will decommission at least one redundant local platform and establish a technology investment forum that includes cyber, risk and business sponsors.
After one year, 95% of privileged access should follow approved patterns, manual assurance effort should fall by 30%, and critical service availability should meet agreed objectives for two quarters. Global scope will be onboarded only after control readiness, with no severe segregation or residency breach. Addressable vendor and tool cost should reduce by 10%.
What the board will measure
- Global expansion enabled on time where controls are ready, and delayed transparently where they are not.
- Complete, decision-useful evidence for access, asset, change and recovery obligations.
- Fewer unsupported exceptions and materially faster onboarding for approved patterns.
- Technology economics reconciled to service demand and expansion benefits.
- Leadership depth across applications, infrastructure, architecture and service management.
The person
You are a CIO, enterprise-technology head or infrastructure and applications executive who has enabled secure cross-border growth. You understand cyber operations without claiming ownership of the security function and can negotiate practical boundaries between enterprise IT, product engineering and defence. Relevant experience includes regulated capability centres, financial services, critical technology and security-sensitive services.
You bring 18–22 years of experience, with accountable technology scope of at least ₹1,800 crore and leadership of 600 people or more. You can point to a business launch you delayed because controls were immature and show how readiness was later proved. Board communication, vendor judgement and incident candour are essential.
This is an onsite Hyderabad appointment due to secure-estate and operational responsibilities.
Compensation and terms
Fixed pay is anticipated at ₹3.2–4.6 crore, supplemented by performance variable and long-term incentives. Objectives will cover expansion readiness, secure service performance, evidence quality, verified simplification and succession. Final calibration depends on scope and current mix, with standard vesting and control-failure protections. The planned process can accommodate up to six months’ notice.
Confidentiality
Client controls, architecture, service providers and global expansion sequence are security-sensitive and absent from this advertisement. Qualified candidates receive controlled disclosure after mutual interest and an undertaking. The Hyderabad location and approximate team size must not be used to infer the organisation.
More seats like this one
This mandate is confidential. The client is named only under a mutual NDA, and your own record is never listed, sold or shown to a company under your name until you release it for this specific mandate.